Live data from Hacker News

Deliveroo users are getting defrauded

newstatesman.com

121–130 of 354 posts

Re: Deliveroo users are getting defrauded

#121
post #113
post #49

Earlier quoted context omitted.

You can find some places that would take fake order in exchange of easy money. Or create a shadow platform where people people can order on Deliveroo with crypto currencies.

Now you’ve gone from petty theft and wire fraud and tacked on criminal conspiracy and god knows what else. This could easily get someone 10 years in jail, right? Not even that hard to investigate because there’s a complete paper trail after a fraud is reported of what was ordered, who delivered it, and where it was delivered.

>Now you’ve gone from petty theft and wire fraud and tacked on criminal conspiracy and god knows what else. This could easily get someone 10 years in jail, right?

That's how the cop would describe it of course. Anyone with half a brain knows they always throw the book but the whole book never sticks.

What sticks will probably wind up being some sort of fraud and the punishment will probably be something like fine and probation.

Re: Deliveroo users are getting defrauded

#122
Of all the job interviews i've done, Deliveroo stands out as the only company that gave me a trick interview test - said specifically not to write a feature, and when I didn't, they rejected me on that ground.

Not surprising their whole business is like this.

Re: Deliveroo users are getting defrauded

#123
post #63

It sounds very much like this journalist is trying to make a mountain out of a mole hill. The real story is that Deliveroo does not handle fraud properly. This is a much lesser crime than what they are being accused of. The author wants to make it seem like Deliveroo has had a data leak and are trying to hide the fact. There is no evidence of this, but if it did turn out to be true then the author would be able to cl…

If I recall, there's no distinction between an en masse data leak and someone being able to access your personal info without authority under GDPR. Both are a data breech. It seems like many people have been affected by this too so clearly Deliveroo doesn't have the mechanisms in place to protect user information. The fact unauthorized people can spend your money through Deliveroo is even worse.

Deliveroo are responsible for the data you give them. If they fuck up and allow unauthorized people access to that data, they're in breech of the GDPR.

If they haven't informed ICO (and equivalent in any country within GDPR rules) within 72 hours of each breech, they're in even deeper shit. First, they have to be clear about the scale of the breech and what exactly has gone wrong. They've got to be able to demonstrate the steps they've taken to mitigate the issue and prevent it happening in future. If people are complaining on a regular basis for months, they've not done that.

Re: Deliveroo users are getting defrauded

#124
post #63

It sounds very much like this journalist is trying to make a mountain out of a mole hill. The real story is that Deliveroo does not handle fraud properly. This is a much lesser crime than what they are being accused of. The author wants to make it seem like Deliveroo has had a data leak and are trying to hide the fact. There is no evidence of this, but if it did turn out to be true then the author would be able to cl…

"The real story is that Deliveroo does not handle fraud properly. This is a much lesser crime than what they are being accused of."

Actually, they're guilty of worse if this were in the USA, they'd be on the hook for aiding and abetting fraud given the sheer number of fraud complaints I see on their Twitter account.

Re: Deliveroo users are getting defrauded

#125

“Deliveroo takes online security very seriously. Sadly fraudsters rely on the fact that people reuse the same passwords on multiple online services to try and gain entry to different accounts across the web.” Yeah! Blame it on your customers! Way to go! Sigh! Another gig economy service I'm damn sure never to use.

That's not even an excuse. There are solutions out there that mitigate the fact people reuse the same passwords.

Re: Deliveroo users are getting defrauded

#126
post #66
post #55

I thought this was going to be about ordering food from one restaurant, only to have it prepared in another 'sublicensed' kitchen, sometimes a shipping container: https://www.theguardian.com/business/2017/oct/28/deliveroo-d...

Is this actually shady? When doing takeaway you are not really paying for the ambiance of the restaurant anyway and IF the quality is the same I wouldn't necessarily have a problem with it.

Well, if I order food from the Fat Duck[1], to name just one example, I expect the restaurant to prepare my food and not some "cook" in a container throwing together some stuff coming from trucks owned by a convenience food purveyor.

So yeah, I think it's shady and dishonest.

Sure, if a restaurant allows their brand to be used for such shenanigans they deserve all the bad press they may get.

Disclaimer: I use the Fat Duck as an example. I'm pretty sure they don't do home deliveries, let alone - Deliveroo.

[1] https://en.wikipedia.org/wiki/The_Fat_Duck

Re: Deliveroo users are getting defrauded

#127
post #17

This is poor form from Deliveroo - their fraud detection seems particularly lacking, and fobbing customers off for months at a time is not good enough. However the article is unnecessarily sensationalist in banding around GDPR data breaches. Much of the article intimates there has been a Deliveroo data breach, whereas in fact the most likely explanation is attackers reusing passwords leaked from other breaches. This…

This comment needs to be the top one on this story. It seems the writer is missing this point entirely. It's very poor practice from Deliveroo and their support team. But there is a big difference between breach through negligence of the data controller and accounts being compromised by user negligence.

How is the data controller NOT negligent given that this has apparently been going on for years AND IT HAS NOT STOPPED? Do we need DECADES of this before you decide Deliveroo isn't doing enough?

Re: Deliveroo users are getting defrauded

#128

I can't understand this fraud - surely getting something delivered to your door is the silliest way to defraud something? Also what are they doing with the £100s of takeaway food they are ordering? I must be missing something here.

You can change delivery address in Deliveroo, maybe they don't make you re-enter payment details like Amazon does when you use a new address? So get into someone's account, use their saved payment to deliver to an arbitrary address and they won't know.

Re: Deliveroo users are getting defrauded

#129

Earlier quoted context omitted.

I've started using privacy.com after I saw a post here on HN about it. It's pretty nice. Basically you link up your bank account and they create debit cards for any online vendors you use, and you can set limits, destroy cards etc. I usually put monthly / transactional limits. Like with Uber Eats I know I only spend x amount, if anybody tried to use my Uber Eats card for 100 USD it would decline it. But also it locks…

> I've started using privacy.com Which is US only. Is there anything like it for the UK?

One could open a MONZO account(Which is completely online and can be opened in a day).(https://monzo.com/)

You would get your debit card within a week max. You can transfer limited amount from your original bank account to Monzo account and even on top of that you can set some restrictions on how much amount can be withdrawn and there are some special features like POTS which are very useful.

I am not saying this is the best, but even if someone steals your monzo card details, you can reqeust for a new one and your original bank card details are still safe.

Note: All this works, only if you don't use a credit card.

Re: Deliveroo users are getting defrauded

#130
post #9

By the sounds of it this is a simple credential reuse attack (it's even states as such in the article) so I really don't see where these accusations of a "data breach", and "encryption, which appears not to have been in place” come from. If these fraudulent transactions are the result of credential reuse I really don't see the GDPR violation here.

It sounds like this could be trivially fixed by requiring re-entering payment details if you order to a new address, like Amazon and others do.
Post reply on HN